Jurisdictions, Five Eyes and privacy
Every company follows the laws of the country it is based in. Those laws decide which authorities can demand data, what process they need, and whether the company can tell users. Privacy Ratings shows each company's jurisdiction on its rating page, in category tables, and on the country pages below.
The Eyes arrangements
The Five Eyes began with the UKUSA Agreement on signals intelligence sharing. The Nine Eyes and Fourteen Eyes are wider sharing arrangements. Intelligence agencies in these countries share data with each other, which can let them receive information about people they could not legally collect themselves.
| Arrangement | Countries |
|---|---|
| Five Eyes | United States, United Kingdom, Canada, Australia, New Zealand |
| Nine Eyes | Five Eyes, plus Denmark, France, the Netherlands and Norway |
| Fourteen Eyes | Nine Eyes, plus Belgium, Germany, Italy, Spain and Sweden |
Sources: UKUSA Agreement, Forward Email technical whitepaper (section 9.5).
How other guides handle jurisdiction
- Privacy Guides requires VPN providers to be "based in a jurisdiction where it cannot be forced to do secret logging," and prefers email providers in "a jurisdiction with strong email privacy protection laws," without naming countries. VPN criteria, email criteria
- That One Privacy Site flagged Five Eyes countries red, Nine and Fourteen Eyes countries yellow, and everything else green. Chart formulas
- EFF's Who Has Your Back rated companies on what they do with government requests: transparency reports, user notice, and requiring warrants. Who Has Your Back
How Privacy Ratings handles it
Jurisdiction appears on each page but does not affect the score. Location alone is a weak signal:
- Proton, in Switzerland and outside all Eyes arrangements, complied with 8,313 of 9,301 legal orders in its most recent yearly report. Source
- Proton VPN, same company and same country, complied with none because it keeps no logs. Source
- Mullvad, in Fourteen Eyes Sweden, has passed audits confirming its VPN servers keep no customer data. Source
The data a provider keeps, and who holds the keys, decide what it can hand over. The scores measure those things: encryption, logging, audits, transparency reports and user notice. Each page still shows the country, its Eyes membership, EU or GDPR coverage, and whether the CLOUD Act applies, so you can weigh jurisdiction yourself.